|
269631
|
5.4 |
MEDIUM
Network
|
schneider-electric
|
bmxnoc0401_firmware bmxnoe0100_firmware bmxnoe0110_firmware bmxnoe0110h_firmware bmxnor0200h_firmware modicon_m340_bmxp342020_firmware modicon_m340_bmxp342020h_firmware modicon_m…
|
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP…
|
CWE-20
Improper Input Validation
|
CVE-2015-6461
|
2024-11-21 11:35 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269632
|
5.9 |
MEDIUM
Network
|
atlassian
|
floodlight
|
Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a stat…
|
CWE-362 CWE-476
Race Condition NULL Pointer Dereference
|
CVE-2015-6569
|
2024-11-21 11:35 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269633
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6544
|
2024-11-21 11:35 |
2018-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269634
|
7.5 |
HIGH
Network
|
oxid-esales
|
eshop
|
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token.
|
CWE-287
Improper Authentication
|
CVE-2015-6926
|
2024-11-21 11:35 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269635
|
6.1 |
MEDIUM
Network
|
puppet
|
puppet_enterprise
|
Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script or HTML via the string parameter, related to Login …
|
CWE-79
Cross-site Scripting
|
CVE-2015-6502
|
2024-11-21 11:35 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269636
|
4.6 |
MEDIUM
Physics
|
grupo_msa
|
vot.ar
|
The parse function in MSA vot.Ar 3.1 does not check whether a candidate receives more than one vote, which allows physically proximate attackers to cast multiple votes for a candidate via a crafted R…
|
CWE-20
Improper Input Validation
|
CVE-2015-6839
|
2024-11-21 11:35 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269637
|
7.5 |
HIGH
Network
|
wp-jobmanager
|
job_manager
|
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object refe…
|
CWE-200
Information Exposure
|
CVE-2015-6668
|
2024-11-21 11:35 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269638
|
6.1 |
MEDIUM
Network
|
web2py
|
web2py
|
Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the _next parameter to user/l…
|
CWE-601
Open Redirect
|
CVE-2015-6961
|
2024-11-21 11:35 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269639
|
6.3 |
MEDIUM
Network
|
saltstack
|
salt_2015
|
salt before 2015.5.5 leaks git usernames and passwords to the log.
|
CWE-200
Information Exposure
|
CVE-2015-6918
|
2024-11-21 11:35 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269640
|
5.4 |
MEDIUM
Network
|
atutor
|
atutor
|
Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6521
|
2024-11-21 11:35 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|